82%
Total Score
healthy
Frequent releases and strong organizational maintenance outweigh the package’s sparse artifact and repository-identification gaps.
The linked repository name does not match the package and its README does not mention @vercel/python, creating some uncertainty about package-specific source ownership; the organization backing partly offsets this concern.
All 24 workflows were analyzed, but one file failed auditing, so coverage is incomplete. High-confidence template-injection findings and many ad hoc package installs are workflow hygiene concerns, while the trusted-publishing finding is informational and no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@vercel/python-analysis Version 0.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.